Comment by OutOfHere
1 hour ago
It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
1 hour ago
It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
Hmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.
a support-initiated reset and transfer would bypass 2fa